Suspicious GitVenom Visual Studio Pre-Build Event Shell Execution via process_creation

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-08
Updated
2026-10-08

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the Visual Studio build engine spawning a command interpreter or PowerShell which is characteristic of a malicious pre-build event script. The GitVenom campaign abused the Visual Studio PreBuildEvent to launch a hidden batch file that deployed cryptocurrency-stealing malware when a victim compiled a trojanized project. Detecting build-time command execution catches supply chain compromise before payloads are staged.

Related detections9 linkedT1059.001 — drag to rearrange
Malicious PowerShell UrlDecode Payload Spawned by SQL Server after FortiClient EMS Exploitation
Suspicious PowerShell Version Pinning with Encoded Command
Suspicious Encoded PowerShell Spawned from Explorer via ClickFix
Suspicious MeshAgent Masquerading as NetworkDrivers Spawned by PowerShell
PowerShell ExportedCommands Array Index for Indirect Cmdlet Execution (Windows Process Creation)
Obfuscated PowerShell Script: Indirect Cmdlet Execution via ExportedCommands Array Index
Malicious Shadow Copy Deletion via WMI PowerShell
Malicious CACTUS Ransomware Deployment via TotalExec Script (via ps_script)
Suspicious PowerShell Remote File Download Cmdlets (via ps_script)
Suspicious GitVenom Visual Studio Pre-Build Event Shell Execution via process_creation
Pivot detection · T1059.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.